Saturday, June 8, 2019

Google Chrome 75 arrives with reader mode, authentication PIN and more

Google Chrome 75

Recently Google has just announced the launch of the new version of its web browser Chrome 75 which comes with news and bug fixes, at the same time, a stable version of the free Chromium project is available, which serves as the core of Chrome.

In addition to the innovations and bug fixes in the new version, 42 vulnerabilities identified by the automated testing tools AddressSanitizer, MemorySanitizer, LibFuzzer and the AFL have been corrected.

No critical problems have been identified that allow all levels of browser protection to be bypassed and code executed on the system outside of the sandbox environment.

As part of the cash rewards program for detecting vulnerabilities in the current version, Google paid 13 prizes worth $ 9,000 (a $ 5,000 bonus, two $ 1,000 prizes and four $ 500 prizes).

Main novelties of Chrome 75

With the arrival of this new version of Google Chrome 75 we can find the compatibility with the FIDO CTAP2 PIN. This has been added to the web authentication API to use a user-defined PIN to authorize operations to the keys that support the FIDO CTAP2 protocol.

In the "Advanced" section of the configurator, you can find an element for "Manage security keys", in which you can assign a PIN code to protect the keys placed in the USB drive, as well as the option to reset the key (delete all data and PIN).

Also within the main changes of this new version we will find the Scroll Snap Stop function that has been added to define the adjustment to the elements during page scrolling (for example, a large scroll gesture when selected in the list of images will result in the election not of the last element, but of the following one).

Another new feature that comes in Google Chrome 75 is the arrival of experimental support for reader mode when it is enabled, only significant text and all associated controls, banners, menus, navigation bars and other parts of the page are displayed. are related to the content are hidden.

Enabling support for the new mode is done with the option chrome: // flags / # enable-reader-mode, after which an item appears in the drop-down menu to use it.

In addition to all users of the desktop version, the default strict site isolation mode is enabled, in which the pages of the different hosts are always located in the memory of the different processes, each of which uses its own test area.

The main feature of the strict isolation mode is the division not by tabs, but by domains, that is, if before the contents of the scripts, the iframe and popup files downloaded from other domains were executed in the same process with the base site , now they will be divided into different processes.

Changes in Google Chrome 75 for Android

In the Android version, the interface of the account parameters in the authentication forms has been improved.

Whereupon the tool information block is now displayed directly on the on-screen keyboard and when clicked on it, the possible saved options are displayed instead of the on-screen keyboard, without hiding the entry form.

Other changes added to Chrome 75

Of the other changes that can be highlighted in this new version of Chrome 75 are that in the sidebar of the debugger, separate information is provided on the state of the breakpoints associated with individual parts of complex expressions on the line (breakpoint) online), for example, methods configured in a chain.

Added support for accessing DNS over HTTPS (DoH, DNS over HTTPS) in the experimental versions of Canary, which can be activated in chrome: // flags # dns-over-https.

DoH can be useful to eliminate leaks of information about requested host names through the providers' DNS servers, combat MITM attacks and replace DNS traffic.
Share:

0 comentarios:

Post a Comment